Protocol and Developer Kit
DNSid is two things, and every page in these docs belongs to one of them. Neither needs an account.
The two layers
Section titled “The two layers”| Layer | What it is | Openness |
|---|---|---|
| The protocol | The IETF Internet-Draft (draft-ihsanullah-dnsid): the _dnsid TXT record, the two-key model, the lifecycle log, and the verification algorithm. Anyone can implement it independently. | Open by definition |
| The Developer Kit | The Go, TypeScript, and Python SDKs, the dnsid CLI with the DNSid Local environment, the cookbook, the conformance suite, and the growing set of integrations. See The Developer Kit. | Open source (Apache-2.0); the CLI and DNSid Local ship as free binaries with source coming soon |
The relationship between the protocol and the kit is the same as TLS to OpenSSL: the protocol is the contract, the kit is one implementation of it, and anything that follows the contract interoperates.
Verifying is always open
Section titled “Verifying is always open”Verifying a DNSid identity needs nothing but DNS and HTTPS. VerifyDomain resolves the agent’s _dnsid TXT record, fetches the JWKS the operator hosts, checks the status URL the operator controls, and validates the lifecycle log the record points to. No central service is in the loop, and no account is required—any relying party on the internet can verify any DNSid identity.
That’s deliberate: the protocol is explicitly designed to avoid a centralized registry that verifiers must trust to be honest and available.
Publishing is yours too
Section titled “Publishing is yours too”A DNSid identity is self-managed: you own the domain, sign your own record with your entity key, and host your own JWKS and status endpoints. Pure protocol, no account. See Publish self-managed records. During development, DNSid Local stands in for your DNS and hosting with a disposable network on your machine, and the same SDK code runs in both places.
Which do I need?
Section titled “Which do I need?”- “I want my service to verify agents that call it.” SDKs only. Start with Verify other agents.
- “I want to try DNSid end to end on my laptop.” DNSid Local, which ships with the free CLI. Nothing leaves your machine.
- “I want an identity on my own domain.” The protocol, self-managed—your DNS, your keys, your endpoints. See Publish self-managed records and Give an agent an identity.
- “I want my agent’s requests to carry its identity.” Sign HTTP requests with RFC 9421, or load the Claude Agent SDK plugin.